Insecure Default Configuration in Dell Wyse ThinOS Products
CVE-2020-29492

10CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
4 January 2021

Summary

Dell Wyse ThinOS versions prior to 8.6 have an insecure default configuration that may allow remote, unauthenticated attackers to gain access to writable files. This vulnerability could enable an attacker to manipulate the configuration settings of targeted devices, potentially leading to further exploitation within a network.

Affected Version(s)

Wyse Proprietary OS (ThinOS) < 8.6

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.